I was just checking my registry and also noticed it appeared as an 020
object in Hijackthis:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
\Notify\!SASWinLogon